Manufacture, production and distribution of chemicals is in Annex 2 to OUG 155/2024. Medium-sized and large companies are important entities, with standard scores of 120 and 180, so the important level in both cases. What sets the sector apart is something else: here, a cyber incident can become a safety incident.
Who is covered by NIS2 in the chemical industry
Annex 2 to OUG 155/2024 takes over the list in the NIS2 Directive, which uses the definitions in Regulation (EC) No 1907/2006 (REACH). It covers:
- undertakings manufacturing substances;
- undertakings distributing substances or mixtures, including chemical wholesalers;
- undertakings producing articles from substances or mixtures, meaning objects whose shape determines their function, for example plastic parts.
Size is set under Law No. 346/2004: as a rule, 50–249 employees for a medium-sized company and 250 or more for a large one. Small and micro companies are covered only in the special cases set out in the law.
Which assurance level applies
| Organisation size | Entity type | Standard risk score | Assurance level | At self-assessment |
|---|---|---|---|---|
| Small or micro | outside NIS2, except for the cases in the law | 60 | basic | 34 controls, threshold 2.5 |
| Medium | important | 120 | important | 133 controls, threshold 3 |
| Large | important | 180 | important | 133 controls, threshold 3 |
The standard score is the DNSC value for the sector, multiplied by 1, 2 or 3 according to size. If you operate in several sectors, the highest score applies.
Find your level and maturity score in a few minutes. The calculator opens with the “Chemicals” sector already selected; you choose the size and answer 12 questions.
Calculate the level for chemicalsWhich systems are assessed in a chemical plant
In a chemical plant, process and safety systems matter as much as the office network. The assessment usually covers:
- the distributed control system and the controllers running the process;
- safety instrumented systems, which shut the process down at dangerous parameters;
- the quality control laboratory and its management system;
- recipes and product documentation, often trade secrets;
- stock management, safety data sheets and transport documents for dangerous goods;
- remote access by equipment and automation suppliers.
Triton: when the target is the safety system
In 2017, at a petrochemical plant in Saudi Arabia, attackers reached the Triconex safety instrumented systems made by Schneider Electric, with purpose-built malware later named Triton or Trisis. A first plant shutdown, in June, was blamed on a mechanical fault. After the second, in August, investigators found the malware. The attackers had been in the company’s IT network for years.
Safety systems are the last barrier before an accident. In the NIS2 assessment they deserve separate treatment: in the inventory, in their own network segment, with remote access limited to what is strictly needed and with every change made only through a procedure.
For companies also covered by the Seveso legislation on major accidents involving dangerous substances, the emergency plan and the cyber incident response plan must fit together: the same team, the same scenarios, the same contacts.
What comes next
- notification to DNSC, within 30 days from the date OUG 155/2024 becomes applicable to the organisation; the first DNSC fine sanctioned exactly this deadline;
- the risk-level assessment, within 60 days of the DNSC decision;
- the self-assessment, within the following 60 days, on the controls of your level;
- the audit, carried out by a DNSC-certified auditor.
How TRU helps
In the chemical industry, testing must not touch the process. We start with:
- PenTest, external and internal, on the IT network and the crossing points to the process network, with reports within 48 hours of the scan being completed; process systems are tested only as planned, with the operator;
- SOC 24/7/365, for plants working in shifts;
- Proton Workspace, for recipes, technical documentation and correspondence with partners, encrypted in transit and at rest, with zero access.
Through CIO-as-a-Service we coordinate the inventory, the relationship with suppliers and the remediation plan. The audit is carried out by DNSC-certified auditors who are TRU partners.
Frequently asked questions
Is a chemical distributor without a plant covered?
Yes, if it is medium-sized or large. Distribution of substances and mixtures is in the annex, not just manufacturing.
We make medicines. Are we covered under chemicals?
No. Manufacturing pharmaceutical products is in the health sector, in Annex 1, with a different score and entity type: a large company is an essential entity.
What level does a large chemical company have?
The important level: the standard score is 180, below the 200 threshold for the essential level. You apply 133 controls, with a threshold of 3 at self-assessment.
Sources
OUG 155/2024 (in Romanian) · Directive (EU) 2022/2555 · DNSC risk-level methodology (in Romanian) · MIT Technology Review, on Triton, 5 March 2019.